Privacy & data

How we handle your data.

This statement covers information collected through this website and through enquiries. Where an engagement involves access to client systems, the engagement contract and any accompanying data processing agreement set the terms and take precedence over this page.

Who we are

Cognito Strategy is an AI transformation and commercial intelligence consultancy based in Dubai, United Arab Emirates. For questions about this statement or about how your data is handled, contact hello@cognitostrategy.com.

Information we collect

We collect only what an enquiry or an engagement requires.

  • Enquiry details — the name, company, work email, role and business challenge you submit through the contact form, plus phone, budget and timeline where you choose to provide them.
  • Correspondence — email and WhatsApp messages you send us, retained as a record of the conversation.
  • Usage data — pages viewed, referral source and approximate location, collected through analytics as described below.
  • Engagement data — during a client engagement, the systems and data access agreed in writing in the engagement contract and any accompanying data processing agreement.

How we use it

We do not sell personal data, and we do not share it with third parties for their own marketing. We do not add enquirers to a marketing list without an explicit request.

  • To respond to your enquiry and arrange an AI Opportunity Session.
  • To prepare and deliver proposals and engagements.
  • To meet legal, accounting and contractual obligations.
  • To understand which parts of this site are useful, in aggregate.

Client data during an engagement

Where an engagement involves access to your systems or data, the terms are set out in the engagement contract and, where applicable, a separate data processing agreement. Those terms take precedence over this statement.

  • Purpose limitation — client data is processed only for the purposes of the engagement.
  • No model training — client data is never used to train general-purpose models.
  • Residency — data residency and processing boundaries are agreed with your information security function before architecture is finalised.
  • Least privilege — access is scoped to what the engagement requires and revoked on completion.
  • Sub-processors — any sub-processor with access to client data is disclosed in writing before it is engaged. A current list is provided in the procurement pack.
  • Retention — engagement data is retained per the contract and deleted or returned on request at completion.

Analytics and tracking

This site uses Google Analytics 4 and, where enabled, the LinkedIn Insight Tag to understand traffic sources and which content is useful. These set cookies in your browser. You can block them through your browser settings or an ad blocker without affecting your use of the site.

We record conversion events — such as a form submission or a booking click — so we can tell which parts of the site lead to a genuine conversation. These events record the action, not the content of your enquiry.

Third-party services

  • Google Analytics — site usage measurement.
  • LinkedIn — advertising measurement, where the Insight Tag is enabled.
  • Calendly — session booking. Data you enter there is subject to Calendly’s own privacy terms.
  • WhatsApp — messaging, subject to WhatsApp’s own terms.
  • Email and CRM — enquiry handling and pipeline management.

Retention

Enquiries that do not lead to an engagement are retained for up to 24 months, then deleted. Engagement records are retained for the period required by contract and by UAE accounting and tax obligations.

Your rights

You may request a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Write to hello@cognitostrategy.com and we will respond within 30 days. Where you are in a jurisdiction granting additional rights — including the UAE Personal Data Protection Law and the UK and EU GDPR — those rights are honoured.

Security

Access to enquiry and client data is restricted to the people delivering the work, protected by multi-factor authentication, and reviewed at engagement close. Where an engagement carries specific security requirements, those are agreed in the contract and implemented in the architecture.

Changes

Material changes to this statement will be reflected in the date below. Where a change affects an active engagement, the client is notified directly.


Last updated: 2026-08-23. Questions: hello@cognitostrategy.com.